CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-5886

Description: A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Eine problematische Schwachstelle wurde in Emlog bis 2.5.7 gefunden. Dies betrifft einen unbekannten Teil der Datei /admin/article.php. Mittels dem Manipulieren des Arguments active_post mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.

CVSS: LOW (3.5)

EPSS Score: 0.04%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49297

Description: Path Traversal vulnerability in Mikado-Themes Grill and Chow allows PHP Local File Inclusion. This issue affects Grill and Chow: from n/a through 1.6.

CVSS: HIGH (8.1)

EPSS Score: 0.06%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49296

Description: Path Traversal vulnerability in Mikado-Themes GrandPrix allows PHP Local File Inclusion. This issue affects GrandPrix: from n/a through 1.6.

CVSS: HIGH (8.1)

EPSS Score: 0.06%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49295

Description: Path Traversal vulnerability in Mikado-Themes MediClinic allows PHP Local File Inclusion. This issue affects MediClinic: from n/a through 2.1.

CVSS: HIGH (8.1)

EPSS Score: 0.06%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49282

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magze allows PHP Local File Inclusion. This issue affects Magze: from n/a through 1.0.9.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49281

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magways allows PHP Local File Inclusion. This issue affects Magways: from n/a through 1.2.1.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49280

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magty allows PHP Local File Inclusion. This issue affects Magty: from n/a through 1.0.6.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49279

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Blogvy allows PHP Local File Inclusion. This issue affects Blogvy: from n/a through 1.0.7.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49278

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Blogty allows PHP Local File Inclusion. This issue affects Blogty: from n/a through 1.0.11.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)

CVE-2025-49277

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Blogprise allows PHP Local File Inclusion. This issue affects Blogprise: from n/a through 1.0.9.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
June 9th, 2025 (about 1 month ago)